Finishes a WebAuthn link: verifies the assertion with the stored key, spends it, and registers the key on the device.
The key's registration attestation decides whether it is attested.
attested
username, sessionId, challenge, credential (what /authn/webauthn.js posted in get mode), origin and rpId
username
sessionId
challenge
credential
/authn/webauthn.js
get
origin
rpId
the register's result, or a refusal
Finishes a WebAuthn link: verifies the assertion with the stored key, spends it, and registers the key on the device.
The key's registration attestation decides whether it is
attested.